Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
1426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.20% | — | Wpbakery Page BuilderAI | 1/9/2026 | 1/9/2026 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 8.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Aplazada | Media (6.1) | 0.38% | — | Codesmiths User Profile BuilderAI | 1/9/2026 | 1/9/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.33% | — | Codesigner User Profile BuilderAI | 1/9/2026 | 1/9/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'date' Shortcode Attribute in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (6.9) | 0.41% | — | Extendthemes Kubio AI Website BuilderAI | 31/8/2026 | 8/9/2026 | Improper input validation vulnerability in Extend Themes Kubio AI Website Builder. This issue affects Kubio AI Website Builder: before 2.9.1. | |
| Aplazada | Media (5.5) | 0.50% | — | Cozmoslabs Profile BuilderAI | 31/8/2026 | 31/8/2026 | A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the file /wp-admin/admin-ajax.php of the component Avatar Simple Upload AJAX Handler. Performing a manipulation results in unrestricted upload. The attack is… | |
| Aplazada | Alta (7) | 0.17% | — | Electron-builderAIMicrosoft Windows InstallerAI | 30/8/2026 | 1/9/2026 | SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables such as TASKKILL by name rather than by absolute path. Because NSIS nsExec::Exec resolves these calls using a search path that… | |
| Aplazada | Alta (8.2) | 0.32% | — | Codesmiths User Profile BuilderAI | 29/8/2026 | 31/8/2026 | The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other… | |
| Aplazada | Media (6.6) | 0.42% | — | Cozmoslabs User Profile BuilderAI | 29/8/2026 | 31/8/2026 | The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The affected feature is a free add-on which is disabled by default, and no POP chain is… | |
| Aplazada | Media (6.8) | 0.43% | — | User Profile BuilderAI | 29/8/2026 | 31/8/2026 | The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as low as contributor to perform Stored Cross-Site Scripting attacks against any user viewing the affected content, including administrators. The shortcode is not enabled by… | |
| Aplazada | Media (4.3) | 0.15% | — | Shopapper Mobile APP BuilderAI | 27/8/2026 | 28/8/2026 | The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock… | |
| Aplazada | Media (6.4) | 0.36% | — | Greenshift Animation AND Page Builder BlocksAI | 26/8/2026 | 26/8/2026 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customapi action handler in versions up to, and including, 12.8.9. This is due to insufficient sanitization of API responses before output via innerHTML. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.8) | 0.92% | — | AvadaAIAvada Fusion BuilderAI | 26/8/2026 | 27/8/2026 | The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it… | |
| Aplazada | Alta (8.6) | 0.53% | — | Shopbuilder PROAI | 24/8/2026 | 24/8/2026 | Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions. | |
| Aplazada | Crítica (9.3) | 0.39% | — | Joomlack Page Builder CKAI | 24/8/2026 | 26/8/2026 | Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the loadStyles method of the frontend page model. | |
| Aplazada | Media (5.3) | 0.44% | — | Joomlack Page Builder CKAI | 24/8/2026 | 26/8/2026 | Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a reflected XSS via the iscontenttype parameter. | |
| Aplazada | Media (4.3) | 0.27% | — | Brave Popup BuilderAI | 23/8/2026 | 26/8/2026 | Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by passing a post ID in the URL. | |
| Aplazada | Alta (7.1) | 0.25% | — | Brave Popup BuilderAI | 23/8/2026 | 26/8/2026 | Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them. | |
| Aplazada | Media (5.3) | 0.56% | — | Themify BuilderAI | 22/8/2026 | 24/8/2026 | The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the stored Themify Builder styling… | |
| Pendiente de análisis | Baja (2.1) | 0.22% | — | Joshnuss XML BuilderAI | 21/8/2026 | 24/8/2026 | XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.element/1, XmlBuilder.element/2, XmlBuilder.element/3.… | |
| Pendiente de análisis | Baja (2.1) | 0.22% | — | Joshnuss XML BuilderAI | 21/8/2026 | 24/8/2026 | XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape/1. The escape/1 clause for {:cdata, data} in… | |
| Pendiente de análisis | Baja (2.1) | 0.19% | — | Joshnuss XML BuilderAI | 21/8/2026 | 24/8/2026 | Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, Cross-site Scripting. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape_string/1,… | |
| Aplazada | Media (4.3) | 0.25% | — | Wptablebuilder WP Table BuilderAI | 18/8/2026 | 20/8/2026 | Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions. | |
| Aplazada | Crítica (9.3) | 0.39% | — | Joomlack Page Builder CKAI | 17/8/2026 | 26/8/2026 | Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the frontend, 3.6.5 in the backend. | |
| Aplazada | Media (6.4) | 0.32% | — | Bold-themes Bold Page BuilderAI | 16/8/2026 | 20/8/2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcode' shortcode in all versions up to, and including, 5.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.5) | 0.45% | — | Webtoffee Extra Product Options Builder FOR WoocommerceAI | 16/8/2026 | 26/8/2026 | The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-uploaded file before serving it, allowing unauthenticated users who obtain a file's stored name to retrieve it. The Extra Product Options Builder for WooCommerce WordPress… |